Public legal documents for the GymPeak iOS app
Last updated: May 29, 2026
This policy describes how your personal data is processed when you use the GymPeak mobile application (the “App”) for iOS. It complies with the EU General Data Protection Regulation 2016/679 (“GDPR”) and the Spanish Organic Law 3/2018 on Data Protection and Digital Rights.
We do not have a Data Protection Officer (DPO), as our processing activities do not meet the thresholds set in Article 37 GDPR.
GymPeak is designed under the principle of data minimization: the App does not send data to any server we control. All data is stored locally on your device. The only data categories are:
startedAt, endedAt) of each session.When you purchase or restore a subscription, we receive only:
We do not receive banking details, card number, billing address, or Apple ID. Apple processes the payment, not us.
| Purpose | Data type |
|---|---|
| Providing App functionality (showing your profile, saving routines, tracking workouts) | Profile and generated data |
| Syncing your data across your own devices via iCloud (if enabled in iPhone Settings) | Profile and generated data |
| Verifying your subscription status and unlocking paid features | Technical subscription data |
We do not perform: profiling, advertising, behavioral analytics, automated decision-making with legal effects, or selling data to third parties.
Your data is not shared with third parties except in the following cases, all necessary for the technical operation of the App:
As a data subject, you can exercise the following rights under Articles 15-22 GDPR:
To exercise them, write to appgympeak@outlook.com with the subject “GDPR Rights” and indicating the right you wish to exercise. We will respond within a maximum of one month from receipt of the request.
Subscriptions are processed on Apple infrastructure, which may involve transfers to the United States. Apple provides adequate safeguards through EU Standard Contractual Clauses (see Apple’s Privacy Policy for details).
The App is intended for users aged 13 and over. If you are between 13 and 16, you must have authorization from a holder of parental responsibility. If we discover we have processed a minor’s data without such authorization, we will delete it without delay.
Data is stored on your device under iOS sandbox protection and, optionally, in iCloud under Apple’s encryption system. We do not transmit data to servers of our own, so there are no risks associated with breaches of our infrastructure.
We may update this policy to reflect changes in the App or in regulations. We will notify you via an in-App notification or a visible change to the “Last updated” date at the top of the document. Previous versions are archived upon request.
If you believe your rights have not been properly addressed, you can file a complaint with the Spanish Data Protection Agency (AEPD) at www.aepd.es. However, we encourage you to contact us first to resolve the matter directly.
Last updated: May 29, 2026 · Version 1.0